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DETAILED ACTION 

1. This office action is in reply to an amendment filed on March 22, 2006. Claims 1-78 are 
pending. 

Response to Arguments 

2. Applicant's arguments filed March 22, 2006 have been fully considered but they are not 
persuasive. Applicant argues that the combination of Zhao (US 6,035,404) and Wood (US 
6,668,322 B1) is improper because Wood teaches away from Zhao. Applicant argues that, 
Wood describes using two separate identifiers within a session credentials structure to identify 
the session and a user. Therefore, the teachings of Zhao to show "a single identifier to identify 
both session and user for all user requests" can't be combined with Wood. Examiner disagrees. 

3. Examiner would point out that Wood teaches the method, comprising receiving a first 
request from a user for an application instance (user request for information resources / 
applications, see columns 4, lines 60-67 and column 5, lines 1-9), the request including a single 
identifier for all user requests without further user and session application variables (i.e., a user 
providing a unique session identifier, that is used for access requests to multiple applications) 
[column 8, lines 13-15, 45-49, and column 10, lines 30-39, 49-53]. Furthermore, it is old and 
well known in the art to identify both a session and a user by a single identifier, which has the 
advantage of allowing flexible control of user logins and session information thereby enhancing 
security of the system. For example, Zhao teaches a user access system including a single 
identifier used to identify both a session and a user for all user requests (i.e., see for example, 
Session ID associated with IUID & Start Time and Time out) [column 5, lines 39-67 and figure 
6]. Examiner would further point out that, to make integral or forming in one piece (i.e., single 
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identifier) an element which has formerly been formed in two pieces (i.e., two separate 
identifiers) and put it together does not patentably distinguish an invention from a prior art. 
Howard v. Detroit Stove Works, U.S. 164 (1893). Examiner asserts that the art on record 
teaches the claimed limitations and therefore the rejection is respectfully maintained. 

Claim Rejections - 35 USC § 103 

4. The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set 
forth in section 102 of this title, if the differences between the subject matter sought to be patented and 
the prior art are such that the subject matter as a whole would have been obvious at the time the 
invention was made to a person having ordinary skill in the art to which said subject matter pertains. 
Patentability shall not be negatived by the manner in which the invention was made. 

5. Claims 1,3-10, 12-20, 22-29, 31-38, 40-49, 51-59, 61-69 and 71-78 are rejected under 
35 U.S.C. 103(a) as being unpatentable over Wood et al. (hereinafter Wood) (US Patent No. 
6,668,322 B1) in view of Zhao US Patent 6,035,404. 

6. As per claims 1 , 7 and 9 Wood teaches a method for performing user and session 
management over a computer network, comprising: 

receiving a first request from a user for an application instance (user request for 
information resources / applications, see columns 4, lines 60-67 and column 5, lines 1-9) , the 
request including a single identifier for all user requests without further user and session 
application variables (i.e., a user providing a unique session identifier, that is used for access 
requests to multiple applications) [column 8, lines 13-15, 45-49, and column 10, lines 30-39, 
49-53]; and 

transmitting an application instance response to the user based on stored user and 
session system information (if session information indicate sufficient authorization providing 
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access to requested application or resource) [column 8, lines 13-25, column 19, lines, 33-44, 
64-67, column 20, lines 1-7 and column 11, lines 12-33]. Wood is silent on a single identifier 
used to identify both a session and a user. However, it is old and well known in the art to identify 
both a session and a user by a single identifier, which has the advantage of allowing flexible 
control of user logins and session information thereby enhancing security of the system. For 
example, Zhao teaches a user access system including a single identifier used to identify both a 
session and a user for all user requests (i.e., see for example, Session ID associated with IUID 
& Start Time and Time out) [column 5, lines 39-67 and figure 6]. Both Wood and Zhao teach a 
method for performing user and session management. It would have been obvious to one 
having ordinary skill in the art at the time of applicant's invention to employ the teachings of 
Zhao within the system of Wood thereby enhancing the security of the system. 

7. As per claim 8, Wood teaches a method for performing user and session management 
over a computer network, comprising: 

a processor, and a memory in communication with the processor, the memory for storing 
a plurality of processing instructions for enabling the processor to (9, lines 65-67, column 10, 
lines 1-29 and column 20, lines 35-60): 

receive a first request from a user for an application instance (user request for 
information resources / applications, see columns 4, lines 60-67 and column 5, lines 1-9) , the 
request including a single identifier for all user requests without further user and session 
application variables (i.e., a user providing a unique session identifier, that is used for access 
requests to multiple applications) [column 8, lines 13-15, 45-49, and column 10, lines 30-39, 
49-53]; and 
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transmit an application instance response to the user based on stored user and session 
system information (if session information indicate sufficient authorization providing access to 
requested application or resource) [column 8, lines 13-25, column 19, lines, 33-44, 64-67, 
column 20, lines 1-7 and column 11, lines 12-33]. Wood is silent on a single identifier used to 
identify both a session and a user. However, it is old and well known in the art to identify both a 
session and a user by a single identifier, which has the advantage of allowing flexible control of 
user logins and session information thereby enhancing security of the system. For example, 
Zhao teaches a user access system including a single identifier used to identify both a session 
and a user for all user requests (i.e., see for example, Session ID associated with IUID & Start 
Time and Time out) [column 5, lines 39-67 and figure 6]. Both Wood and Zhao teach a method 
for performing user and session management. It would have been obvious to one having 
ordinary skill in the art at the time of applicant's invention to employ the teachings of Zhao within 
the system of Wood thereby enhancing the security of the system. 

8. As per claims 10, 17 and 19, Wood teaches a method for performing user and session 
management over a computer network, comprising: 

receiving a request for an application instance from a user (user request for information 
resources / applications[columns 4, lines 60-67 and column 5, lines 1-9]; 

assigning a single identifier to the user for handling all user requests(i.e., providing a 
unique session identifier to a user, that is used for access requests to multiple applications) 
[column 8, lines 13-15, 45-49, and column 10, lines 30-39, 49-53]; and 
transmitting an application instance response to the user, wherein the single identifier is static 
for all requests from the user for a session [column 8, lines 13-25, column 19, lines, 33-44, 64- 
67, column 20, lines 1-7 and column 11, lines 12-33]. Wood is silent on a single identifier used 



Application/Control Number: 09/812,634 Page 6 

Art Unit: 2135 

to identify both a session and a user. However, it is old and well known in the art to identify both 
a session and a user by a single identifier, which has the advantage of allowing flexible control 
of user logins and session information thereby enhancing security of the system. For example, 
Zhao teaches a user access system including a single identifier used to identify both a session 
and a user for all user requests (i.e., see for example, Session ID associated with IUID & Start 
Time and Time out) [column 5, lines 39-67 and figure 6]. Both Wood and Zhao teach a method 
for performing user and session management It would have been obvious to one having 
ordinary skill in the art at the time of applicant's invention to employ the teachings of Zhao within 
the system of Wood thereby enhancing the security of the system. 

9. As per claim 18, Wood teaches an apparatus for performing user and session 
management over a computer network, comprising: 

a processor, and a memory in communication with the processor, the memory for 
storing a plurality of processing instructions for enabling the processor to (9, lines 65-67, column 

10, lines 1-29 and column 20, lines 35-60): 

receive a request for an application instance from a user (user request for information 
resources / applications )[columns 4, lines 60-67 and column 5, lines 1-9]; 

assign a single identifier to the user for handling all user requests(i.e., providing a unique 
session identifier to a user, that is used for access requests to multiple applications) [column 8, 
lines 13-15, 45-49, and column 10, lines 30-39, 49-53]; and 

transmit an application instance response to the user, wherein the single identifier is static for all 
requests from the user for a session [column 8, lines 13-25, column 19, lines, 33-44, 64-67, 
column 20, lines 1-7 and column 11, lines 12-33]. Wood is silent on a single identifier used to 
identify both a session and a user. However, it is old and well known in the art to identify both a 
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session and a user by a single identifier, which has the advantage of allowing flexible control of 
user logins and session information thereby enhancing security of the system. For example, 
Zhao teaches a user access system including a single identifier used to identify both a session 
and a user for all user requests (i.e., see for example, Session ID associated with IUID & Start 
Time and Time out) [column 5, lines 39-67 and figure 6]. Both Wood and Zhao teach a method 
for performing user and session management. It would have been obvious to one having 
ordinary skill in the art at the time of applicant's invention to employ the teachings of Zhao within 
the system of Wood thereby enhancing the security of the system. 

10. As per claims 20, 26 and 28, Wood teaches a method for performing user and session 
management over a computer network, comprising: 

receiving a first request from a user for a first application instance, the first request 
including an identifier (user request for information resources / applications)[columns 4, lines 60- 
67, column 5, lines 1-9, column 8, lines 13-15, 45-49, and column 10, lines 30-39, 49-53]; 

transmitting a first application instance response to the user [column 19, lines 64-67, 
column 20, lines 1-8 and column 9, lines 40-63]; 

receiving a second request from the user for a second application instance, the 
second request including the identifier, and processing the request with the second application 
instance [column 19, lines 64-67, column 20, lines 1-8 and column 9, lines 40-63]. Wood is 
silent on a single identifier used to identify both a session and a user. However, it is old and well 
known in the art to identify both a session and a user by a single identifier, which has the 
advantage of allowing flexible control of user logins and session information thereby enhancing 
security of the system. For example, Zhao teaches a user access system including a single 
identifier used to identify both a session and a user for all user requests (i.e., see for example, 
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Session ID associated with IUID & Start Time and Time out) [column 5, lines 39-67 and figure 
6]. Both Wood and Zhao teach a method for performing user and session management. It would 
have been obvious to one having ordinary skill in the art at the time of applicant's invention to 
employ the teachings of Zhao within the system of Wood thereby enhancing the security of the 
system. 

11. As per claim 27, Wood teaches an apparatus for performing user and session 
management over a computer network, comprising: 

a processor, and a memory in communication with the processor, the memory for storing 
a plurality of processing instructions for enabling the processor to (9, lines 65-67, column 10, 
lines 1-29 and column 20, lines 35-60): 

receive a first request from a user for a first application instance, the first request 
including an identifier (user request for information resources / applications)[columns 4, lines 60- 
67, column 5, lines 1-9, column 8, lines 13-15, 45-49, and column 10, lines 30-39, 49-53]; 

transmit a first application instance response to the user [column 19, lines 64-67, column 
20, lines 1-8 and column 9, lines 40-63]; 

receive a second request from the user for a second application instance, the 
second request including the identifier, and processing the request with the second application 
instance [column 19, lines 64-67, column 20, lines 1-8 and column 9, lines 40-63]. Wood is 
silent on a single identifier used to identify both a session and a user. However, it is old and well 
known in the art to identify both a session and a user by a single identifier, which has the 
advantage of allowing flexible control of user logins and session information thereby enhancing 
security of the system. For example, Zhao teaches a user access system including a single 
identifier used to identify both a session and a user for all user requests (i.e., see for example, 
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Session ID associated with IUID & Start Time and Time out) [column 5, lines 39-67 and figure 
6]. Both Wood and Zhao teach a method for performing user and session management. It would 
have been obvious to one having ordinary skill in the art at the time of applicant's invention to 
employ the teachings of Zhao within the system of Wood thereby enhancing the security of the 
system. 

12. As per claims 29, 36-38, 44 and 46, Wood teaches a method for performing user and 
session management over a computer network, comprising: 

receiving, from a user, a first request in a first session, the request including an identifier 
(note that unique session identifier is used for access requests to multiple applications) [column 
8, lines 13-15, 45-49, and column 10, lines 30-39, 49-53]; 

transmitting a first application instance response to the user in response to the first 
request [column 19, lines 64-67, column 20, lines 1-8 and column 9, lines 40-63]; 

receiving, from the user, a second request in a second session, the second user request 
including the identifier, and processing the second request through the first application instance 
[column 19, lines 64-67, column 20, lines 1-8 and column 9, lines 40-63]. Wood is silent on a 
single identifier used to identify both a session and a user. However, it is old and well known in 
the art to identify both a session and a user by a single identifier, which has the advantage of 
allowing flexible control of user logins and session information thereby enhancing security of the 
system. For example, Zhao teaches a user access system including a single identifier used to 
identify both a session and a user for all user requests (i.e., see for example, Session ID 
associated with IUID & Start Time and Time out) [column 5, lines 39-67 and figure 6], Both 
Wood and Zhao teach a method for performing user and session management. It would have 
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been obvious to one having ordinary skill in the art at the time of applicant's invention to employ 
the teachings of Zhao within the system of Wood thereby enhancing the security of the system. 

13. As per claims 35 and 45, Wood teaches an apparatus for performing user and session 
management over a computer network, comprising (9, lines 65-67, column 10, lines 1-29 and 
column 20, lines 35-60): 

a processor, and a memory in communication with the processor, the memory for storing 
a plurality of processing instructions for enabling the processor to (9, lines 65-67, column 10, 
lines 1-29 and column 20, lines 35-60): 

receive, from a user, a first request in a first session, the request including an identifier 
[column 8, lines 13-15, 45-49, and column 10, lines 30-39, 49-53]; 

transmit a first application instance response to the user in response to the first request 
[column 19, lines 64-67, column 20, lines 1-8 and column 9, lines 40-63]; 

receive, from the user, a second request in a second session, the second user request 
including the identifier, and process the second request through the first application instance 
[column 19, lines 64-67, column 20, lines 1-8 and column 9, lines 40-63]. Wood is silent on a 
single identifier used to identify both a session and a user. However, it is old and well known in 
the art to identify both a session and a user by a single identifier, which has the advantage of 
allowing flexible control of user logins and session information thereby enhancing security of the 
system. For example, Zhao teaches a user access system including a single identifier used to 
identify both a session and a user for all user requests (i.e., see for example, Session ID 
associated with IUID & Start Time and Time out) [column 5, lines 39-67 and figure 6]. Both 
Wood and Zhao teach a method for performing user and session management. It would have 



Application/Control Number: 09/81 2,634 Page 1 1 

Art Unit: 2135 

been obvious to one having ordinary skill in the art at the time of applicant's invention to employ 
the teachings of Zhao within the system of Wood thereby enhancing the security of the system. 

14. As per claims 47, 55 and 57, Wood teaches a method for performing user and session 
management over a computer network, comprising: 

receiving a first request from a first user session for a user, the first request including an 
identifier [column 19, lines 64-67, column 20, lines 1-8 and column 9, lines 40-63]; and 

transmitting a first response to the first request, based on the identifier and a first system 
session variable stored in a user database (if session information indicate sufficient 
authorization providing access to requested application or resource) [column 8, lines 13-25, 
column 19, lines, 33-44, 64-67, column 20, lines 1-7 and column 11, lines 12-33]; 

receiving a second request from a second user session for the user, the second request 
including the identifier without further user or session application variables, and transmitting a 
second response to the second request, based on the identifier and a second system session 
variable stored in the user database [column 19, lines 64-67, column 20, lines 1-8 and column 
9, lines 40-63]. Wood is silent on a single identifier used to identify both a session and a user. 
However, it is old and well known in the art to identify both a session and a user by a single 
identifier, which has the advantage of allowing flexible control of user logins and session 
information thereby enhancing security of the system. For example, Zhao teaches a user 
access system including a single identifier used to identify both a session and a user for all user 
requests (i.e., see for example, Session ID associated with IUID & Start Time and Time out) 
[column 5, lines 39-67 and figure 6]. Both Wood and Zhao teach a method for performing user 
and session management. It would have been obvious to one having ordinary skill in the art at 



Application/Control Number: 09/812,634 Page 12 

Art Unit: 2135 

the time of applicant's invention to employ the teachings of Zhao within the system of Wood 
thereby enhancing the security of the system. 

15. As per claim 56, Wood teaches an apparatus for performing user and session 
management over a computer network, comprising: 

a processor, and a memory in communication with the processor, the memory for storing 
a plurality of processing instructions for enabling the processor to (9, lines 65-67, column 10, 
lines 1-29 and column 20, lines 35-60): 

receive a first request from a first user session for a user, the first request including an 
identifier [column 19, lines 64-67, column 20, lines 1-8 and column 9, lines 40-63]; and 

transmit a first response to the first request, based on the identifier and a first system 
session variable stored in a user database (if session information indicate sufficient 
authorization providing access to requested application or resource) [column 8, lines 13-25, 
column 19, lines, 33-44, 64-67, column 20, lines 1-7 and column 11, lines 12-33]; 

receive a second request from a second user session for the user, the second request 
including the identifier without further user or session application variables, and transmitting a 
second response to the second request, based on the identifier and a second system session 
variable stored in the user database [column 19, lines 64-67, column 20, lines 1-8 and column 
9, lines 40-63]. Wood is silent on a single identifier used to identify both a session and a user. 
However, it is old and well known in the art to identify both a session and a user by a single 
identifier, which has the advantage of allowing flexible control of user logins and session 
information thereby enhancing security of the system. For example, Zhao teaches a user 
access system including a single identifier used to identify both a session and a user for all user 
requests (i.e., see for example, Session ID associated with IUID & Start Time and Time out) 
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[column 5, lines 39-67 and figure 6]. Both Wood and Zhao teach a method for performing user 
and session management. It would have been obvious to one having ordinary skill in the art at 
the time of applicant's invention to employ the teachings of Zhao within the system of Wood 
thereby enhancing the security of the system. 

16. As per claims 58 t 65 and 67, Wood teaches a method for performing user and session 
management over a computer network, comprising: 

receiving a first request from a first user, the first request including a first identifier 
corresponding to the first user [column 5, lines 1-9, column 8, lines 13-15, 45-49, and column 
10, lines 30-39, 49-53]; 

receiving a second request from a second user, the second request including a 
second identifier corresponding to the second user (note that a unique session identifier is 
provided for users, i.e., during request for resources users include the unique session 
identifier) [column 8, lines 13-15, 45-49, and column 10, lines 30-39, 49-53]; and 

generating a first application instance responsive to the first identifier and a second 
application instance responsive to the second identifier [column 8, lines 13-25, column 19, lines, 
33-44, 64-67, column 20, lines 1-7 and column 11, lines 12-33]. Wood is silent on a single 
identifier used to identify both a session and a user. However, it is old and well known in the art 
to identify both a session and a user by a single identifier, which has the advantage of allowing 
flexible control of user logins and session information thereby enhancing security of the system. 
For example, Zhao teaches a user access system including a single identifier used to identify 
both a session and a user for all user requests (i.e., see for example, Session ID associated 
with IUID & Start Time and Time out) [column 5, lines 39-67 and figure 6]. Both Wood and Zhao 
teach a method for performing user and session management. It would have been obvious to 
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one having ordinary skill in the art at the time of applicant's invention to employ the teachings of 
Zhao within the system of Wood thereby enhancing the security of the system. 

17. As per claim 66, Wood teaches an apparatus for performing user and session 
management over a computer network, comprising: 

a processor, and a memory in communication with the processor, the memory for storing 
a plurality of processing instructions for enabling the processor to (9, lines 65-67, column 10, 
lines 1-29 and column 20, lines 35-60): 

receive a first request from a first user, the first request including a first identifier 
corresponding to the first user [column 5, lines 1-9, column 8, lines 13-15, 45-49, and column 
10, lines 30-39, 49-53]; 

receive a second request from a second user, the second request including a 
second identifier corresponding to the second user (note that a unique session identifier is 
provided for users, i.e., during request for resources users include the unique session 
identifier) [column 8, lines 13-15, 45-49, and column 10, lines 30-39, 49-53]; and 

generate a first application instance responsive to the first identifier and a second 
application instance responsive to the second identifier [column 8, lines 13-25, column 19, lines, 
33-44, 64-67, column 20, lines 1-7 and column 11, lines 12-33]. Wood is silent on a single 
identifier used to identify both a session and a user. However, it is old and well known in the art 
to identify both a session and a user by a single identifier, which has the advantage of allowing 
flexible control of user logins and session information thereby enhancing security of the system. 
For example, Zhao teaches a user access system including a single identifier used to identify 
both a session and a user for all user requests (i.e., see for example, Session ID associated 
with IUID & Start Time and Time out) [column 5, lines 39-67 and figure 6]. Both Wood and Zhao 
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teach a method for performing user and session management. It would have been obvious to 
one having ordinary skill in the art at the time of applicant's invention to employ the teachings of 
Zhao within the system of Wood thereby enhancing the security of the system. 

18. As per claim 68, Wood teaches a method for performing user and session management 
over a computer network, comprising: 

receiving, from a first user, a first request in a first session, the first request including a 
first identifier [column 5, lines 1-9, column 8, lines 13-15, 45-49, and column 10, lines 30-39, 
49-53]; 

transmitting a first application instance to the first user in response to the first request 
[column 19, lines 64-67, column 20, lines 1-8 and column 9, lines 40-63]; 

receiving, from the first user, a second request in a second session, the second request 
including the first identifier, and processing the second request through the first application 
instance [column 19, lines 64-67, column 20, lines 1-8 and column 9, lines 40-63]; 

receiving, from a second user, a third request in a third user session, the third request 
including a second identifier corresponding to the second user (note that a unique session 
identifier is provided for users, i.e., during request for resources users include the unique 
session identifier) [column 8, lines 13-15, 45-49, and column 10, lines 30-39, 49-53]; and 
transmitting a second application instance to the second user in response to the third request 
[column 8, lines 13-25, column 19, lines, 33-44, 64-67, column 20, lines 1-7 and column 11, 
lines 12-33]. Wood is silent on a single identifier used to identify both a session and a user. 
However, it is old and well known in the art to identify both a session and a user by a single 
identifier, which has the advantage of allowing flexible control of user logins and session 
information thereby enhancing security of the system. For example, Zhao teaches a user 



Application/Control Number: 09/812,634 Page 16 

Art Unit: 2135 

access system including a single identifier used to identify both a session and a user for all user 
requests (i.e., see for example, Session ID associated with IUID & Start Time and Time out) 
[column 5, lines 39-67 and figure 6]. Both Wood and Zhao teach a method for performing user 
and session management. It would have been obvious to one having ordinary skill in the art at 
the time of applicant's invention to employ the teachings of Zhao within the system of Wood 
thereby enhancing the security of the system. 

19. As per claims 75 and 77, Wood teaches a method for interacting A method for 
interacting with a central server over a computer network, comprising: 

transmitting a first request to a central server, the first request including a user identifier 
[column 5, lines 1-9, column 8, lines 13-15, 45-49, and column 10, lines 30-39, 49-53]; 

receiving a first application instance in response to the first request [column 19, lines 64- 
67, column 20, lines 1-8 and column 9, lines 40-63]; and 

transmitting a second request to the central server, the second request including the 
identifier without further user or session application variables [column 19, lines 64-67, column 
20, lines 1-8 and column 9, lines 40-63]; and 

receiving a response to the second request from the application instance [column 19, 
lines 64-67, column 20, lines 1-8 and column 9, lines 40-63]. Wood is silent on a single identifier 
used to identify both a session and a user. However, it is old and well known in the art to identify 
both a session and a user by a single identifier, which has the advantage of allowing flexible 
control of user logins and session information thereby enhancing security of the system. For 
example, Zhao teaches a user access system including a single identifier used to identify both a 
session and a user for all user requests (i.e., see for example, Session ID associated with IUID 
& Start Time and Time out) [column 5, lines 39-67 and figure 6]. Both Wood and Zhao teach a 
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method for performing user and session management. It would have been obvious to one 
having ordinary skill in the art at the time of applicant's invention to employ the teachings of 
Zhao within the system of Wood thereby enhancing the security of the system. 

20. As per claims 3, 13, 23, 31, 40, 51, 61 and 71, Wood further teaches the method further 
comprising: authenticating an identification of the user [column 8, lines 19-25, column 13, lines 
37-67]; and assigning the single identifier to the user [column 14, lines 43-67, column 3, lines 
13-18]. 

21 . As per claim 4, 14, 24, 32, 41 , 52, 62 and 72, Wood further teaches the method wherein 
said authenticating comprises: 

transmitting a request for a user name and a password to the user [column 7, lines 1- 

24]; 

receiving the user name and password from the user [column 7, lines 1-24, and column 
13, lines 60-67]; and 

comparing the user name and password to stored parameters [column 13, lines 43-47 
and 7, lines 30-33]. 

22. As per claims 5, 15, 33, 42, 53, 63 and 73, Wood further teaches the method further 
comprising: 

receiving a second (third / fourth) request form the user for a second application 
instance, the second request including the identifier, and processing the request with the 
application instance [column 19, lines 64-67, column 20, lines 1-8 and column 9, lines 40-63]. 
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23. As per claims 6 and 16, Wood further teaches the method further comprising: 
receiving a second request from a second user, the second request including a second 

identifier corresponding to the second user (note that a unique session identifier is provided for 
users, i.e., during request for resources users include the unique session identifier) [column 8, 
lines 13-15, 45-49, and column 10, lines 30-39, 49-53]; and 

generating a second application instance responsive to the second identifier [column 19, 
64-67, column 20, lines 1-7 and column 9, lines 40-63]. 

24. As per claims 12, 22, 48, 49, 59, 69, 76 and 78, Wood further teaches the method, 
wherein the identifier does not include user or session application variables for use by the 
application instance (unique session identifier, that is used for access requests to multiple 
applications) [column 8, lines 13-15, 45-49, and column 10, lines 30-39, 49-53]. 

25. As per claims 25, 34, 43, 54, 64 and 74, Wood further teaches the method further 
comprising: 

receiving a third request from a second user, the second request including a second 
identifier corresponding to the second user (note that a unique session identifier is provided for 
users, i.e., during request for resources users include the unique session identifier) [column 8, 
lines 13-15, 45-49, and column 10, lines 30-39, 49-53]; and 

generating a second application instance responsive to the second identifier [column 19, 
64-67, column 20, lines 1-7 and column 9, lines 40-63]. 

26. Claims 2, 11, 21, 30, 39, 50, 60 and 70 are rejected under 35 U.S.C. 103(a) as being 
unpatentable over Wood (US Patent No. 6,668,322 B1) in view of Zhao US Patent 6,035,404 as 
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applied above and further in view of Gupta et al. 
B1). 
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(hereinafter Gupta) (US Patent No. 6,226,752 



27. As per claims 2, 1 1 , 21 , 30, 39, 50, 60 and 70, Wood-Zhao teaches the method as 
applied above. Furthermore, Wood teaches assigning a single identifier to the user for handling 
all user requests (i.e., providing a unique session identifier to a user, that is used for access 
requests to multiple applications) [column 8, lines 13-15, 45-49, and column 10, lines 30-39, 49- 
53]. Wood does not explicitly teach the method wherein the single identifier includes a random 
number associated with the user. However Gupta teaches an authentication and session 
management system including a session identifier that includes a random number associated 
with the user [column 6, lines 21-35]. Therefore it would have been obvious to one having 
ordinary skill in the art at the time the invention was made to incorporate a session identifier that 
includes a random number associated with a user as per teachings of Gupta into the session 
management system of Wood-Zhao, because random generated identifier uniquely identify a 
user for session management with multiple applications. 

Conclusion 

THIS ACTION IS MADE FINAL. Applicant is reminded of the extension of time policy 
as set forth in 37 CFR 1.136(a). 

A shortened statutory period for reply to this final action is set to expire THREE 
MONTHS from the mailing date of this action. In the event a first reply is filed within TWO 
MONTHS of the mailing date of this final action and the advisory action is not mailed until after 
the end of the THREE-MONTH shortened statutory period, then the shortened statutory period 
will expire on the date the advisory action is mailed, and any extension fee pursuant to 37 
CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, 
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however, will the statutory period for reply expire later than SIX MONTHS from the mailing date 
of this final action. 

Any inquiry concerning this communication or earlier communications from the examiner 
should be directed to Beemnet W. Dada whose telephone number is (571) 272-3847. The 
examiner can normally be reached on Monday - Friday (9:00 am - 5:30 pm). 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Kim Y. Vu can be reached on (571) 272-3859. The fax phone number for the 
organization where this application or proceeding is assigned is 571-273-8300. 

Information regarding the status of an application may be obtained from the Patent 
Application Information Retrieval (PAIR) system. Status information for published applications 
may be obtained from either Private PAIR or Public PAIR. Status information for unpublished 
applications is available through Private PAIR only. For more information about the PAIR 
system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private 
PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you 
would like assistance from a USPTO Customer Service Representative or access to the 
automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 



Beemnet Dada 
May 26, 2006 




